Selasa, 06 Maret 2012
Revealed: Technical Surveillance Threats
Spy Cam 101
Not long ago while on assignment, I was asked "How many times do you actually find technical surveillance threats?"
My answer was "Well, I would tell you but then I would have to...." Just kidding, The real answer is more often than you would think..
Although, not every technical surveillance threat involves finding a device. It can also can mean discovering a technical surveillance vulnerability. Like for instance, the allowance of cellular devices (w/ cameras) or iPads in conference rooms and during high level meetings. Or, the allowance of digital recorders within these areas, just to name a few.
It's not always "James Bond" spy gear that turns up during a sweep.
But every now and then, I still discover a "surprise" that may (or may not) have been left behind...on purpose.
For example, take this pen & pencil holder discovered during the wee hours of the morning while sweeping the "Presidential Suite" of one of our clients facilities.
Plain looking enough, but take a closer look... Through our Thermal Imaging Camera... Notice that hot spot? So did we...It turned out to be a hardwired Spy cam, with audio....Here's another look..
This was only one of the technical surveillance threats found during this assignment. Yes, you heard me right, only one of several threats found...
So, the short answer is YES, technical surveillance threats (although crude) like the above are used for intel collection purposes by your adversaries. i.e.; disgruntled employee, competitor, corp spy, eavesdropper, etc.
So be aware, these types of surveillance threats could be lurking closer than you might think...
If you don't mind me asking, When was your last TSCM Sweep? Not Sure? Contact Me here. I can help.
Stay tuned for the next "reveal"....JDL
Kamis, 23 Februari 2012
IT and espionage on Wall Street
An overturned conviction creates uncertainty about what constitutes a crime
Selasa, 14 Februari 2012
Traveling Light in a Time of Digital Thievery
nytimes.com
SAN FRANCISCO — When Kenneth G. Lieberthal, a China expert at the Brookings Institution, travels to that country, he follows a routine that seems straight from a spy film.
He leaves his cellphone and laptop at home and instead brings “loaner” devices, which he erases before he leaves the United States and wipes clean the minute he returns. In China, he disables Bluetooth and Wi-Fi, never lets his phone out of his sight and, in meetings, not only turns off his phone but also removes the battery, for fear his microphone could be turned on remotely. He connects to the Internet only through an encrypted, password-protected channel, and copies and pastes his password from a USB thumb drive. He never types in a password directly, because, he said, “the Chinese are very good at installing key-logging software on your laptop.”
What might have once sounded like the behavior of a paranoid is now standard operating procedure for officials at American government agencies, research groups and companies that do business in China and Russia — like Google, the State Department and the Internet security giant McAfee. Digital espionage in these countries, security experts say, is a real and growing threat — whether in pursuit of confidential government information or corporate trade secrets.
More...
Jumat, 30 Desember 2011
Cameramaker Red claims espionage
In a saga worthy of a Hollywood thriller, allegations of email hacking and industrial espionage have surfaced in the camera industry in a lawsuit filed by digital camera maker Red against rival Arri.
Selasa, 22 November 2011
Compliance vs. Security: The Multiple Dimensions of Corporate Espionage
Senin, 31 Oktober 2011
Cyber spy campaign targets chemical industry: Symantec
Jumat, 28 Oktober 2011
German secret police arrest elderly Spies "Mr. & Mrs. Smith"
Israel Convicts Conspirator Who Wiretapped Michael Cherney
According to the original indictment, filed in January 2011 by the Israel State Attorney's office, Eskin was contacted in 2007 by a Russian citizen, Alexei Drobashenko, who asked him to gather information about Michael Cherney in order to use it in a smear campaign.
Russian spies suspected of stealing auto secrets from Germans
A married couple was arrested in the German town Michelbach, suspected of stealing secrets from German car manufacturers, after it emerged one of them worked in the auto industry for the past 20 years.
“intelligence service sources say the man, named only as Andreas A., had worked for Faurecia, one of Germany’s top car part manufacturers which supplies major companies including Volkswagen, Renault, Toyota and Ford,” where he is thought to have engaged in “industrial espionage.”
Minggu, 23 Oktober 2011
FBI: Tech firms face spy risk
Kexue Huang, a scientist and native of China, pleaded guilty last week in a federal court to swiping millions of dollars worth of trade secrets from Dow Chemical Co. and Cargill Inc. for other people doing research in Germany and China.
A federal jury last month ordered South Korea's Kolon Industries to pay DuPont Co. $920 million for stealing trade secrets regarding synthetic fibers used in such products as Kevlar body armor. A former DuPont engineer hired by Kolon, Michael Mitchell of Virginia, was sentenced in March last year to 18 months in prison for theft of trade secrets for passing on key DuPont data to Kolon.
And area technology companies are likely fooling themselves if they think they're not in the cross-hairs of such spy efforts, according to the Federal Bureau of Investigation. "If you haven't been a victim yet, it's because you have been and you don't know it, or you will be," Barry W. Couch, a special agent with FBI's Buffalo division, told a conference room full of area optics industry executives last week. "Don't be blindsided."
Chili's Sydor Optics played host as the FBI spent a handful of hours talking about counterintelligence and economic espionage issues, with handouts and a video presentation all revolving around the message that companies are under siege by foreign economic competitors, often with explicit help from foreign governments.
Optics in particular "is a targeted industry," said FBI special agent Chad Kaestle. Other frequently targeted technologies include sensors, aeronautics and marine systems.
Jumat, 07 Oktober 2011
SpearTip’s Top Cyber Counterespionage Expert Gives TV Interview on TRICARE Data Theft
Doubts custodian’s assurances. Fears possible extortion of military employees whose personal medical data was taken.
Rabu, 05 Oktober 2011
Social media for corporate networking or corporate espionage?
Today, corporates are looking at social media like Twitter, LinkedIn and Facebook to broaden their online outreach. In a session at INTEROP Mumbai 2011, Abilash Sonwane, Senior-VP, Elitecore Technologies, talked about how social media networks are the next frontier of corporate espionage
Around 13 percent of corporate losses occur due to corporate espionage, as per a recent KPMG report. The number is less as most of the companies usually don’t admit it. In a session at INTEROP Mumbai 2011, Abilash Sonwane, Senior-VP, Elitecore Technologies, talked about how social media networks are the next frontier of corporate espionage.
Today, corporates are looking at social media like Twitter, LinkedIn and Facebook to broaden their online outreach. As per Nielsen Online study, social networking is now officially more popular then e-mail. Considering the popularity of social media among corporates, Elitecore Technologies did a research on 20 companies to find out how social media can be used for corporate espionage.
To conduct the research, Elitecore selected companies that were active on social media from a mix of industries and geographies. The company found out that though on one hand social media can enable an enterprise to enhance its relationship with customers, on the other hand it can adversely affect a company’s reputation.
More...
Jumat, 30 September 2011
kmov.com(KMOV) -- Wednesday night, TRICARE, the health care program for millions of military members, retirees, and their families announced a data breach that affects an estimated 4.9 million people.
Read TRICARE's statement here: www.tricare.mil/mybenefit/Download/Forms/DataBreach_PublicStatement.pdf
Science Applications International Corporation reported that one of its employees was driving backup computer tapes from one federal office to another in San Antonio, Texas. At one point, the car was broken into and the backup tapes were stolen. SAIC says it won't disclose how many tapes were taken, but says only "some" were encrypted.
The tapes that were lost included names, Social Security numbers, addresses, and medical treatment information of patients who were treated at San Antonio military treatment facilities (or patients who have had lab work processes there) from 1992 until September 7, 2011.
TRICARE and SAIC say they are working to identify all the beneficiaries whose information may have been lost and notify the affected people. TRICARE says that the risk of harm to patients is low because the thief would have to have access to specific hardware and software and know how to pull the data from the tapes.
Jarrett Kolthoff, who runs a cyber security firm called SpearTip, LLC, says people should be concerned.
"It doesn't take a rocket scientist to grab that information and than use that data in a nefarious manner," said Kolthoff.
"If it was unencrypted, my concern would be the leverage that somebody could use against individuals."
Rabu, 28 September 2011
The Best Spies Money Can Buy
darkreading.comIn June, security firm FireEye detected evidence of such a connection when it found instances of a remote-access Trojan whose code seemed to have been reused to infect machines with fake antivirus software. In another incident, cybercriminals sold access to compromised military and government computers, allowing would-be cyberspies to get direct access to their targets, says Darien Kindlund, senior staff scientist at FireEye.
The two examples are part of a building body of evidence that suggests attackers representing what the military and security industry refer to as the advanced persistent threat (APT) are not shying away from using criminals' resources to help them in their missions.
"If military and government hosts are being sold on the black market, who are the most likely buyers -- spammers?' No, they could buy something cheaper on a different network. But for APT?'Yes, it meets their mission objectives," Kindlund says.
Selasa, 20 September 2011
Defence contractor warns of false cyber security beliefs
crn.com.auFour 'mindsets' that trip up specialists.
BAE Systems Australia's cyber security head has warned against four mindsets preventing security specialists from effectively dealing with cyber threats.
According to the defence contractor's Tim Scully, an overemphasis on all-encompassing defensive measures or on compliance with standards or regulations could be counterproductive.
Scully, who was also the chief executive officer of BAE subsidiary Stratsec, chaired a work group on Cyber Threat and Fortress Mentality at the second national cyber warfare conference in Canberra this week.
Fortress mindset
He described the "fortress mindset" as the traditional approach to security, where specialists aimed to keep all threats outside of their networks.
Defensive measures in a "fortress" approach focused on systems and infrastructure rather than focusing on protecting the organisation's most valuable information.
That approach was as naïve as thinking that everything inside the network was secure, he said.
“If your network is connected to the Internet, and you have something of value to a threat actor, you are likely already compromised," he said.
More...Minggu, 18 September 2011
Espionage Research Institute (ERI) 2011 Conference

Espionage Research Institute (ERI) 2011 Conference
The 2011 ERI Conference brought together a group of leading edge counterintelligence practitioners that respond to crisis situations and espionage incidents from both foreign and domestic threats.
FOR IMMEDIATE RELEASE
Sept 18, 2011 - The 2011 ERI Conference brought a group of these counterespionage agents out of the shadows for a brief moment to share information with their brethren. The threats levied against corporations from either electronic surveillance (bugs) or the latest threats from malware (Advance Persistent Threats) require these specialists to keep abreast of the latest threats. Adhering to ERI’s motto: "The Biggest Mistake That We Can Make Would Be To Miss The Changes", and their membership meets annually to ensure they remain aware of the changes in the espionage industry and can effectively detect threats.
This year’s keynote address from Jarrett Kolthoff, CEO – SpearTip, a former U.S. Counterintelligence Agent, addressed the threats levied against corporations from both foreign and domestic competitors. Mr. Kolthoff provided insight on how many corporations are responding to these incidents and are holding the rogue employee and/or competitor accountable for their actions.
Other presenters at the conference brought some of their latest technology, such as the OSCOR GREEN from Research Electronics International (REI) The OSCOR Green was designed for commercial applications to detect illicit eavesdropping signals, perform site surveys for communications systems, conduct radio frequency (RF) emissions analysis, and investigate misuse of the RF spectrum.
AIR Patrol Corp, shared their latest in cellular detection technology.
Global TSCM Corp brought their latest technology and gave a TSCM products demo.
Professional Development TSCM Group Inc., presented on the Kestrel TSCM TM Professional Software a Canadian designed and developed TSCM total RF collection and analysis solution; scalable to address all operational threat levels.
Walleye Technologies, Inc. presented their new portable microwave imaging device for a wide variety of applications that require handheld imaging and microwave capabilities.
Other notable presentations from ERI members and TSCM Specialists included:
"The Future of TSCM" by Steve Whitehead, of Eavesdropping Detection Solutions. Gauteng, South Africa.
"GSM & Hybird Cellular Threats" by Jason Dibley & James Williams of QCC Interscan Ltd. London UK.
"TSCM" Inside Out" by Julian Claxton of Jayde Consulting Pty Ltd. Sydney, Australia
"Computer Security" by Dr. Gordon Mitchell of Future Focus, Inc. Washington State. USA.
"TSCM Challenges Today" by Ed Steinmetz of Steinmetz Associates. Philadelphia, Penn.
"Power Line Analysis using a SDR" by Michael Dever of Dever Clark & Associates of Canberra, Australia.
"Security Podcast Resources and building a network VoIP Tap" by Charles Patterson of Patterson Communications. Tarrytown, NY.
Glenn Whidden, President of ERI and a former CIA officer, created ERI in an effort to bring together TSCM specialists, security practitioners, businessmen and corporate security executives to share information about hostile global espionage activity directed against business and industry. This year’s event was chaired by J.D. LeaSure, President/CEO of ComSec LLC, which resulted in another tremendous success in bringing together this international consortium of "spy hunters". J.D. will also Chair next year’s event at ERI's Annual Membership Conference (To Be Announced). The conference will continue to highlight current and emerging threats, detection methods and effective countermeasures.
Each year, U.S. businesses lose billions of dollars to Corporate Espionage, Industrial Espionage and Economic Espionage. ERI's membership consists of a small, exclusive group of global Technical Surveillance Countermeasures (TSCM) and Cyber Counterintelligence experts whose private businesses are tasked with detecting and neutralizing the threats against your corporation.
For more information please contact ERI Conference chairman, J. D. LeaSure at: jd.leasure@espionageresearchinstitute.org or Ph: 703-910-3330
The Espionage Research Institute is dedicated to collecting and promulgating information on hostile espionage activity, which is done through the process of accepting, screening and editing reports of hostile activity as they are received from ERI Associates and its Advisors.
Rabu, 14 September 2011
How hackers find their targets
experian.comThe rash of large-scale data breaches in the news this year begs many questions, one of which is this: how do hackers select their victims?
The answer: research.
Hackers do their homework; in fact, an actual hack typically takes place only after many hours of first studying the target.
Here’s an inside look at a hacker in action:
- Using search queries through such resources as Google and job sites, the hacker creates an initial map of the target’s vulnerabilities. For example, job sites can offer a wealth of information such as hardware and software platform usage, including specific versions and its use within the enterprise.
- The hacker fills out the map with a complete intelligence database on your company, perhaps using public sources such as government databases, financial filings and court records. Attackers want to understand such details as how much you spend on security each year, other breaches you’ve suffered, and whether you’re using LDAP or federated authentication systems.
- The hacker tries to identify the person in charge of your security efforts. As they research your Chief Security Officer or Chief Intelligence Security Officer (who they report to, conferences attended, talks given, media interviews, etc.) hackers can get a sense of whether this person is a political player or a security architect, and can infer the target’s philosophical stance on security and where they’re spending time and attention within the enterprise.
Jumat, 09 September 2011
Researchers’ Typosquatting Stole 20 GB of E-Mail From Fortune 500 Companies
wiredTwo researchers who set up doppelganger domains to mimic legitimate domains belonging to Fortune 500 companies say they managed to vacuum up 20 gigabytes of misaddressed e-mail over six months.
The intercepted correspondence included employee usernames and passwords, sensitive security information about the configuration of corporate network architecture that would be useful to hackers, affidavits and other documents related to litigation in which the companies were embroiled, and trade secrets, such as contracts for business transactions.
“Twenty gigs of data is a lot of data in six months of really doing nothing,” said researcher Peter Kim from the Godai Group. “And nobody knows this is happening.”
Doppelganger domains are ones that are spelled almost identically to legitimate domains, but differ slightly, such as a missing period separating a subdomain name from a primary domain name – as in the case of seibm.com as opposed to the real se.ibm.com domain that IBM uses for its division in Sweden.
Kim and colleague Garrett Gee, who released a paper this week (.pdf) discussing their research, found that 30 percent, or 151, of Fortune 500 companies were potentially vulnerable to having e-mail intercepted by such schemes, including top companies in consumer products, technology, banking, internet communication, media, aerospace, defense, and computer security.
More...Jumat, 26 Agustus 2011
Engineers convicted in Goodyear corporate espionage case
tyrepress.comA US federal judge has sentenced two former Wyko engineers to four years probation and 150 hours of community service after they were convicted of convicted of stealing trade secrets from Goodyear Tire and Rubber Co. in a corporate espionage case that first surfaced in 2009.
According to the Knoxville News Sentinel, federal prosecutors had wanted US district court judge Thomas W. Phillips to give Clark Alan Roberts and Sean Edward Howley at least 10 months in prison, but their lack of previous convictions and “ample” family and community support reportedly won out.
A jury found Roberts and Howley each guilty in December on 10-counts alleging they conspired to steal and use trade secrets. Roberts and Howley, who were employees of Wyko Tire Technology Inc. at the time, had been accused of visiting Goodyear’s Topeka, Kansas plant in 2007 so Howley could use his camera phone to take pictures OTR tyre production procedures.
During the trial Tom Frey, a consultant for Goodyear and a former Goodyear manager, had estimated it cost $520,000 to develop the design drawings for the equipment the defendants were convicted of photographing and that Goodyear made $17 million in 2007 from the sale of tyres that machine produces. However Judge Phillips rejected Frey as a witness and noted that he was not employed by Goodyear and had not produced documentation to verify these figures.
More...
Rabu, 17 Agustus 2011
Corporate cybercrime tops boardroom agenda
freshbusinessthinking.comHigh profile corporate cybercrime is putting information security on boardroom agendas around the world, a global survey revealed on Wednesday.
The need for increased measures to protect against corporate espionage and network hacking, the accidental or deliberate leaking of corporate data, and the loss or theft of company laptops, has never been so high, company bosses told the British Standards Institution (BSI), the leading business service for the development of standards, in a survey.
According to the research, which analyses responses from 645 businesses, risk of corporate data leaks is a key concern. Two thirds (64%) of the surveyed businesses that have implemented ISO 27001 (an information security management system) cited this as the most important driving force behind adopting the information security standard.
In addition to risk, the BSI research also shows that 72% of businesses are worried about the financial damage of cybercrime.
More...













